Messages by Thread
-
[ANNOUNCE] Apache Lucene 9.11.0 released
Benjamin Trent
-
[ANNOUNCE] Apache ServiceComb Java Chassis version 3.1.2 Released
liubao
-
[ANNOUNCE] Apache Jackrabbit 2.21.27-beta released
Julian Reschke
-
[ANNOUNCE] Apache Commons JEXL 3.4.0
Gary Gregory
-
[ANNOUNCE] Apache Pulsar Helm Chart version 3.4.1 Released
Lari Hotari
-
[ANNOUNCE] Apache NetBeans 22 released
Eric Barboni
-
[ANNOUNCE] Apache Commons JCS 3.2.1
Thomas Vandahl
-
CVE-2024-36104: Apache OFBiz: Path traversal leading to a RCE
Jacques Le Roux
-
[ANNOUNCE] Apache Airflow Providers prepared on May 30, 2024 are released
Elad Kalif
-
[ANNOUNCE] Apache Kyuubi released 1.9.1
Cheng Pan
-
[ANNOUNCE] Apache FreeMarker 2.3.33 is released
Daniel Dekany
-
[ANNOUNCE] Apache Wicket 9.18.0 released
Andrea Del Bene
-
[ANNOUNCE] Apache Wicket 10.1.0 released
Andrea Del Bene
-
[ANNOUNCE] Apache Commons Net 3.11.0
Gary Gregory
-
[ANNOUNCE] Apache OFBiz 18.12.14 released
Jacopo Cappellato
-
[ANNOUNCE] Release Apache Hop 2.9.0
Bart Maertens
-
[ANNOUNCE] Apache Airflow Providers prepared on May 26, 2024 are released
Elad Kalif
-
[ANNOUNCE] Apache Solr 9.6.1 released
Houston Putman
-
[ANNOUNCE] Apache Arrow nanoarrow 0.5.0 Released
Dewey Dunnington
-
[ANNOUNCE] Apache Jackrabbit Oak 1.64.0 released
Julian Reschke
-
[ANNOUNCE] Apache Pekko HTTP 1.1.0-M1 released
PJ Fanning
-
[ANNOUNCE] Apache XMLBeans 5.2.1 release
PJ Fanning
-
[ANN] Apache Maven 3.9.7 released
Slawomir Jaranowski
-
[ANNOUNCE] Apache Impala 4.4.0 release
Zoltán Borók-Nagy
-
[ANNOUNCE] Apache HBase 2.4.18 is now available for download
Duo Zhang
-
[ANNOUNCEMENT] Commons Daemon 1.4.0 Released
Mark Thomas
-
[ANNOUNCE] Apache Commons CLI Version 1.8.0
Gary Gregory
-
[ANN] Apache Syncope 3.0.7
Francesco Chicchiriccò
-
[ANNOUNCE] Apache YuniKorn v1.5.1 released
Wilfred Spiegelenburg
-
[ANNOUNCE] Apache Arrow ADBC 12 released
David Li
-
[ANNOUNCE] Hive 2.x EOL
Ayush Saxena
-
[ANNOUNCE] Apache Arrow 16.1.0 released
Raúl Cumplido
-
[ANNOUNCE] Apache Pekko 1.1.0-M1 released
PJ Fanning
-
[ANNOUNCE] Apache NiFi MiNiFi C++ 0.99.0 release
Gábor Gyimesi
-
[ANNOUNCE] Apache Sedona 1.6.0 released
Jia Yu
-
[ANNOUNCE] Apache Airflow Providers prepared on May 12, 2024 are released
Elad Kalif
-
[ANNOUNCE] Apache Pulsar 3.2.3 released
Lari Hotari
-
[ANNOUNCE] Apache Pulsar 3.0.5 released
Lari Hotari
-
[ANNOUNCE] Apache Flink CDC 3.1.0 released
Qingsheng Ren
-
[ANNOUNCE] Apache NiFi 2.0.0-M3 Released
David Handermann
-
[ANNOUNCE] Released Reactive client for Apache Pulsar, version 0.5.5
Chris Bono
-
[ANNOUNCE] Apache StormCrawler (Incubating) 3.0 released
Richard Zowalla
-
[ANNOUNCE] Apache Commons Logging 1.3.2
Gary Gregory
-
[ANNOUNCE] Apache ServiceComb Java Chassis version 3.1.1 Released
liubao
-
CVE-2024-32077: Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
Ephraim Anierobi
-
[ANN] Apache Tomcat 10.1.24 Available
Christopher Schultz
-
[ANNOUNCEMENT] Apache SkyWalking BanyanDB 0.6.0 Released
Hongtao Gao
-
[ANNOUNCE] Apache SkyWalking 10.0.0 released
Sheng Wu
-
[ANNOUNCE] Apache Jackrabbit 2.20.16 released
Julian Reschke
-
[ANNOUNCE] Apache Camel 4.6.0 Released
Gregor Zurowski
-
[ANNOUNCE] Apache Sedona 1.5.3 released
Jia Yu
-
CVE-2024-34365: Apache Karaf Cave: Cave SSRF and arbitrary file access
Arnout Engelen
-
CVE-2024-26579: Apache Inlong JDBC Vulnerability
Charles Zhang
-
CVE-2024-32113: Apache OFBiz: Path traversal leading to RCE
Jacques Le Roux
-
[ANN] Apache Tomcat 11.0.0-M20 (alpha) available
Mark Thomas
-
[ANNOUNCE] Apache Sedona 1.5.2 released
Jia Yu
-
[ANN] Apache Tomcat 9.0.89 available
Rémy Maucherat
-
[ANNOUNCE] Apache SkyWalking BanyanDB Java Client 0.6.0 released
Hongtao Gao
-
[ANNOUNCE] Apache OFBiz 18.12.13 released
Jacopo Cappellato
-
CVE-2024-28148: Apache Superset: Incorrect datasource authorization on explore REST API
Daniel Gaspar
-
[ANNOUNCE] Apache Calcite 1.37.0 released
Sergey Nuyanzin
-
[ANNOUNCE] Apache Geronimo BatchEE 2.0.0
fpapon
-
[ANNOUNCE] Apache Camel 3.22.2 (LTS) Released
Gregor Zurowski
-
[ANNOUNCE] Apache Airflow 2.9.1 Released
Ephraim Anierobi
-
[ANNOUNCE] Apache Airflow Providers prepared on May 01, 2024 are released
Elad Kalif
-
Apache Archiva is now retired
Hervé Boutemy
-
CVE-2023-35701: Apache Hive: Arbitrary command execution via JDBC driver
Stamatis Zampetakis
-
Apache Bahir is now retired
Hervé Boutemy
-
CVE-2024-32114: Apache ActiveMQ: Jolokia and REST API were not secured with default configuration
Jean-Baptiste Onofré
-
[ANNOUNCE] Apache Nutch 1.20 Release
lewis john mcgibbney
-
[ANNOUNCE] Apache Arrow 16.0.0 released
Raúl Cumplido
-
[ANNOUNCE] Apache APISIX 3.9.1 has been released
Xin Rong
-
[ANNOUNCE] Apache APISIX 3.8.1 has been released
Xin Rong
-
[ANN] Apache ActiveMQ Classic 6.1.2 has been released!
Jean-Baptiste Onofré
-
[ANNOUNCE] Apache Solr 9.6.0 released
Gus Heck
-
[ANNOUNCE] Apache Commons Codec 1.17.0
Gary Gregory
-
[ANNOUNCE] Apache Commons BCEL Version 6.9.0
Gary Gregory
-
[ANNOUNCE] Apache Kyuubi 1.8.2 is available
Cheng Pan
-
[ANNOUNCE] Apache Kyuubi 1.7.4 is available
Cheng Pan
-
[ANNOUNCE] Apache Camel 4.0.5 (LTS) Release
Gregor Zurowski
-
[ANNOUNCE] Apache bRPC 1.9.0 released
Shuai Liu
-
[ANNOUNCE] Apache Camel 4.4.2 (LTS) Released
Gregor Zurowski
-
[ANNOUNCE] OpenNLP 2.3.3 released
Martin Wiesner
-
[ANNOUNCE] Apache Pulsar C# Client DotPulsar 3.2.1 released
David Jensen
-
CVE-2024-27349: Apache HugeGraph-Server: Bypass whitelist in Auth mode
Imba Jin
-
CVE-2024-27348: Apache HugeGraph-Server: Command execution in gremlin
Imba Jin
-
[ANNOUNCE] Apache IoTDB 1.3.1 released
Haonan Hou
-
CVE-2024-27347: Apache HugeGraph-Hubble: SSRF in Hubble connection page
Imba Jin
-
[ANNOUNCE] Apache Airflow Providers prepared on April 16, 2024 are released
Elad Kalif
-
[ANNOUNCE] Apache Pulsar Helm Chart version 3.4.0 Released
Lari Hotari
-
[ANN] Apache Struts 6.4.0
Lukasz Lenart
-
[ANNOUNCEMENT] Apache CloudStack LTS Maintenance Release 4.18.2.0
João Jandre
-
CVE-2024-29733: Apache Airflow FTP Provider: FTP_TLS instance with unverified SSL context
Elad Kalif
-
[ANNOUNCE] Apache Pulsar Client Python 3.5.0 released
Yunze Xu
-
[ANNOUNCE] Apache ServiceComb Java Chassis version 3.1.0 Released
liubao
-
[ANNOUNCE] Apache ServiceComb Java Chassis version 2.8.16 Released
liubao
-
CVE-2024-29217: Apache Answer: XSS vulnerability when changing personal website
Enxin Xie
-
[ANNOUNCE] Apache Commons Imaging 1.0.0-alpha5
Gary Gregory
-
[ANNOUNCE] Apache Geronimo XBean 4.25 released
fpapon
-
[ANNOUNCE] Apache Commons CLI Version 1.7.0
Gary Gregory
-
[ANNOUNCE] Apache Pulsar Node.js client 1.11.0 released
Baodi Shi
-
CVE-2024-31869: Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Ephraim Anierobi
-
[ANNOUNCE] Apache Commons Text Version 1.12.0
Gary Gregory
-
[ANNOUNCE] Apache Hive 1.x EOL
Stamatis Zampetakis
-
[ANN] Apache Tomcat 9.0.88 available
Rémy Maucherat
-
[ANN] Apache Tomcat 11.0.0-M19 (alpha) available
Rémy Maucherat
-
[ANNOUNCE] Apache Airflow Providers prepared on April 13, 2024 are released
Elad Kalif
-
[ANNOUNCE] Apache Qpid proton-dotnet 1.0.0-M10 released
Timothy Bish
-
[ANN] Apache TomEE 9.1.3
Richard Zowalla
-
[ANNOUNCE] Released Reactive client for Apache Pulsar, version 0.5.4
Chris Bono
-
[ANNOUNCE] Apache Airflow Providers prepared on April 10, 2024 are released
Elad Kalif
-
[ANNOUNCE] Apache Solr Operator v0.8.1 released
Jason Gerlowski
-
CVE-2024-31391: Apache Solr Operator: Solr-Operator liveness and readiness probes may leak basic auth credentials
Jason Gerlowski
-
CVE-2024-27309: Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
Colin McCabe
-
[ANNOUNCE] Apache Geronimo Arthur 1.0.9 released
fpapon
-
[ANN] Apache ActiveMQ "Classic" 5.18.4 has been released!
Jean-Baptiste Onofré
-
[ANNOUNCE] Apache BookKeeper 4.16.5 released
Nicolò Boschi
-
[ANNOUNCE] Apache Superset version 4.0.0 released
Michael S. Molina
-
[ANN] Apache TomEE 10.0.0-M1
Richard Zowalla
-
CVE-2024-31861: Apache Zeppelin: Code injection by Shell interpreter
Jongyoul Lee
-
CVE-2024-31309: Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Bryan Call
-
[ANNOUNCE] Apache Daffodil 3.7.0 Released
Steve Lawrence
-
DotPulsar version 3.2.0
David Jensen
-
CVE-2024-31867: Apache Zeppelin: LDAP search filter query Injection Vulnerability
Jongyoul Lee
-
CVE-2024-31864: Apache Zeppelin: Remote code execution by adding malicious JDBC connection string
Jongyoul Lee
-
CVE-2024-31868: Apache Zeppelin: XSS vulnerability in the helium module
Jongyoul Lee
-
CVE-2024-31866: Apache Zeppelin: Interpreter download command does not escape malicious code injection
Jongyoul Lee
-
CVE-2024-31865: Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
Jongyoul Lee
-
[ANNOUNCE] Apache Commons IO 2.16.1
Gary Gregory
-
[ANNOUNCE] Apache Kyuubi Shaded released 0.4.0
Cheng Pan
-
[ANNOUNCE] Apache Jackrabbit Oak 1.62.0 released
Julian Reschke
-
[ANNOUNCE] Apache Groovy 4.0.21 released
Paul King
-
[ANNOUNCE] Apache Groovy 5.0.0-alpha-8 released
Paul King
-
CVE-2024-31863: Apache Zeppelin: Replacing other users notebook, bypassing any permissions
Jongyoul Lee
-
CVE-2024-31862: Apache Zeppelin: Denial of service with invalid notebook name
Jongyoul Lee
-
CVE-2022-47894: Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE
Jongyoul Lee
-
CVE-2021-28656: Apache Zeppelin: CSRF vulnerability in the Credentials page
Jongyoul Lee
-
CVE-2024-31860: Apache Zeppelin: Path traversal vulnerability
Jongyoul Lee
-
[ANNOUNCE] Apache Airflow 2.9.0 Released
Ephraim Anierobi
-
[ANNOUNCE] Apache APISIX 3.9.0 has been released
Abhishek Choudhary
-
[ANNOUNCE] Apache Guacamole 1.5.5 released
Michael Jumper
-
[ANNOUNCE] Apache Storm 2.6.2 Released
Richard Zowalla
-
[ANN] Apache ActiveMQ 6.1.1 has been released!
Jean-Baptiste Onofré
-
CVE-2024-24746: Apache NimBLE: Denial of service in NimBLE Bluetooth stack
Szymon Janc
-
[ANNOUNCE] Apache Kafka 3.6.2
Manikumar
-
[ANNOUNCE] Apache Calcite Avatica 1.25.0 Released
Francis Chuang
-
CVE-2024-27316: Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Eric Covener
-
CVE-2023-38709: Apache HTTP Server: HTTP response splitting
Eric Covener
-
CVE-2024-24795: Apache HTTP Server: HTTP Response Splitting in multiple modules
Eric Covener
-
[ANNOUNCE] Apache Mynewt 1.12.0 and Apache Mynewt NimBLE 1.7.0 released
Szymon Janc
-
[ANNOUNCEMENT] Apache HTTP Server 2.4.59 Released
covener
-
[ADVISORY] Apache CloudStack Security Releases 4.18.1.1 and 4.19.0.1
Rohit Yadav
-
[ANNOUNCE] Release Apache Traffic Control 8.0.1
R S
-
[ANNOUNCE] Apache Traffic Server 9.2.4 and 8.1.10 are released
Bryan Call
-
[ANNOUNCE] Apache Airflow Providers prepared on March 25, 2024 are released
Jarek Potiuk
-
[ANNOUNCE] Apache Commons Collections 4.5.0-M1
Gary Gregory
-
[ANNOUNCE] Apache Commons Imaging 1.0.0-alpha4
Gary Gregory
-
[ANNOUNCE] Apache Tika 2.9.2 released
Tim Allison
-
CVE-2024-29834: Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints
Lari Hotari
-
[ANNOUNCE] Apache Hive 4.0.0 Released
Ayush Saxena
-
[ANNOUNCE] Apache Pulsar 3.2.2 released
Lari Hotari
-
[ANNOUNCE] Apache Pulsar Client C++ 3.5.1 released
Yunze Xu
-
[ANNOUNCE] Apache Pulsar 3.0.4 released
Lari Hotari
-
[ANNOUNCE] Apache Zeppelin 0.11.1 available
Jongyoul Lee
-
[ANNOUNCE] Apache Johnzon 2.0.1
Markus Jung
-
[ANNOUNCEMENT] Apache SkyWalking Rover 0.6.0 Released
han liu
-
CVE-2024-23539: Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Arnout Engelen
-
CVE-2024-23538: Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Arnout Engelen
-
CVE-2024-23537: Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role.
Arnout Engelen
-
[ANNOUNCE] Apache SpamAssassin 4.0.1 available
Sidney Markowitz
-
[ANNOUNCE] Apache Jena 5.0.0 released
Andy Seaborne
-
[ANNOUNCE] Apache Qpid protonj2 1.0.0-M20 released
Timothy Bish
-
[ANNOUNCE] Apache Camel 4.5.0 Released
Gregor Zurowski
-
[ANNOUNCE] Apache Jackrabbit 2.21.26-beta released
Julian Reschke
-
[ANNOUNCE] Apache CloudStack CloudMonkey v6.4.0
Rohit Yadav
-
CVE-2024-29735: Apache Airflow: Potentially harmful permission changing by log task handler
Jarek Potiuk
-
[ANNOUNCE] Apache Geronimo BatchEE 1.0.4
fpapon
-
[ANN] Apache Tomcat 10.1.20 Available
Christopher Schultz
-
[ANN] Apache Tomcat 8.5.100 Available
Christopher Schultz
-
[ANNOUNCE] Apache Airflow Helm Chart version 1.13.1 Released
Jedidiah Cunningham
-
[ANNOUNCE] Apache Pinot 1.1.0 released
Vivek Iyer Vaidyanathan Iyer
-
[ANNOUNCE] Apache Flink Kubernetes Operator 1.8.0 released
Maximilian Michels
-
[ANNOUNCE] Apache PDFBox 2.0.31 released
Andreas Lehmkühler
-
[ANNOUNCEMENT] Apache SkyWalking Cloud on Kubernetes 0.9.0 Released
Ye Cao
-
[ANNOUNCE] Apache SystemDS 3.2.0
Janardhan
-
[ANNOUNCE] Apache Pulsar Helm Chart version 3.3.1 Released
Lari Hotari
-
CVE-2024-26307: Apache Doris: Possible race condition
Mingyu Chen
-
CVE-2024-27438: Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution
Mingyu Chen
-
CVE-2024-29131: Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Gary D. Gregory
-
CVE-2024-29133: Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Gary D. Gregory
-
[ANNOUNCE] Apache Commons Configuration 2.10.1
Gary Gregory
-
[ANNOUNCE] Apache Arrow 15.0.2 released
Raúl Cumplido
-
[ANN] Apache Tomcat 11.0.0-M18 (alpha) available
Mark Thomas
-
[ANNOUNCE] Release Apache Hop 2.8.0
Bart Maertens
-
CVE-2024-27439: Apache Wicket: Possible bypass of CSRF protection
Emond Papegaaij
-
[ANNOUNCE] Apache Kyuubi released 1.9.0
Binjie Yang